new-product-tracker

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose, and there is no direct malware or payload execution signal. The main concern is data-flow integrity: product queries and the required API key are routed through Nexscope proxy endpoints instead of official source APIs, creating an intermediary trust dependency that is only partially transparent. Overall this looks more like a legitimate but trust-expanding analytics skill than malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jun 28, 2026, 07:07 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fnew-product-tracker%2F@ba82121c4c39b620671b60b67bb00f6571057bb105b68234f73a1af905a2a381
Security Audit — socket — new-product-tracker